2.4 KiB
Executable file
2.4 KiB
Executable file
Claude Code — Project Configuration
Shared knowledge: Read
AGENTS.mdat repo root for architecture, patterns, rules, and operations. This file adds Claude-specific features on top.
Claude-Specific Resources
- Skills:
.claude/skills/(7 active). Archived runbooks:.claude/skills/archived/ - Agents:
.claude/agents/cluster-health-checker(haiku, autonomous health checks) - Reference:
.claude/reference/— patterns.md, service-catalog.md, proxmox-inventory.md, github-api.md, authentik-state.md - GitHub API:
curlwith tokens from tfvars (ghCLI blocked by sandbox)
Instructions
- "remember X": Update this file +
AGENTS.md(if shared knowledge), commit with[ci skip] - Apply with SOPS: Use
scripts/tgwrapper instead of rawterragrunt— auto-decrypts secrets - New services need CI/CD (Woodpecker) and monitoring (Prometheus/Uptime Kuma)
- New service: Use
setup-projectskill for full workflow - Ingress:
ingress_factorymodule. Auth:protected = true. Anti-AI: on by default. - Docker images: Always build for
linux/amd64(docker buildx build --platform linux/amd64). Pull-through cache serves stale :latest — use versioned tags. - Node memory changes: When changing VM memory on any k8s node, update kubelet
systemReserved,kubeReserved, and eviction thresholds accordingly. Config:/var/lib/kubelet/config.yaml. Template:stacks/infra/main.tf. Current values: systemReserved=512Mi, kubeReserved=512Mi, evictionHard=500Mi, evictionSoft=1Gi. - Sealed Secrets: User-managed secrets go in
sealed-*.yamlfiles in the stack directory. Stacks pick them up viakubernetes_manifest+fileset(path.module, "sealed-*.yaml"). See AGENTS.md for full workflow.
Known Issues
- CrowdSec Helm upgrade times out:
terragrunt applyon platform stack causes CrowdSec Helm release to get stuck inpending-upgrade. Workaround:helm rollback crowdsec <rev> -n crowdsec. Root cause: likely ResourceQuota CPU at 302% preventing pods from passing readiness probes. Needs investigation.
User Preferences
- Calendar: Nextcloud at
nextcloud.viktorbarzin.me - Home Assistant: ha-london (default), ha-sofia. "ha"/"HA" = ha-london
- Frontend: Svelte for all new web apps
- Tools: Docker containers only — never
brew installlocally - Pod monitoring: Never use
sleep— spawn background subagent withkubectl get pods -w